CVE-2023-29983
MEDIUMcompanymaps 8.0 - Stored Cross-Site Scripting in Admin Audit Log Tab
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2023-29983. PoCs published by Lucas Noki (0xPrototype), zPrototype.
AI-analyzed exploit summary This exploit demonstrates a stored XSS vulnerability in Companymaps V8.0 via the 'token' parameter in the /rest/update/ endpoint. The payload steals admin cookies when viewed in the audit log.
Description
Cross Site Scripting vulnerability found in Maximilian Vogt cmaps v.8.0 allows a remote attacker to execute arbitrary code via the auditlog tab in the admin panel.
Exploits (2)
This exploit demonstrates a stored XSS vulnerability in Companymaps V8.0 via the 'token' parameter in the /rest/update/ endpoint. The payload steals admin cookies when viewed in the audit log.
This repository contains a detailed writeup for CVE-2023-29983, a stored XSS vulnerability in cmaps version 8.0. The exploit involves injecting a malicious payload via the 'token' parameter in the /rest/update/ endpoint, which is later executed when an admin views the audit log.
References (4)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N